MALICIOUS — buvarazilexigosox.pdf
MALICIOUS — buvarazilexigosox.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 4 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
e3082e8be69f59c630aad65b58b70f9adb604eaaa9fd2634b089602c32705217 - SHA-1:
9b2bd68520c6d0c1354c5765a0935d12a95fa824 - MD5:
3230a2dd1d4c74600477762670de1a5c - ssdeep:
1536:AgvO9ejp7XWLef5gF4A8WsUui01wXeWx5clhhdWBH1PuFglkpRYWspO23tt:TljZC9VkfwXeWxj1GFgSrz2r - TLSH:
T16B38BFF320D7ED9C374B9B47A9BB21A9B05EE7885232D79060887A2CD47C17D7B00A41 - Submitted as: buvarazilexigosox.pdf
- File type: pdf · Size: 77050 bytes
- Verdict: malicious (96/100)
Detections (4 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 (rule
Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: http://piazzademarini3ge.com/userfiles/files/situkawonunivawanidegojuw.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://huntic.ru/uplcv?utm_term=kabir+singh+full+hd+movie+download+1080p, http://jubangh.com/Upload/FckUpload/20210903file///5343820692.pdf, https://iveducentar.com/uploads/assets/file/93376470185.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://huntic.ru/uplcv?utm_term=kabir+singh+full+hd+movie+download+1080p
- http://jubangh.com/Upload/FckUpload/20210903file///5343820692.pdf
- https://iveducentar.com/uploads/assets/file/93376470185.pdf
- http://sonarkella.com/userfiles/file/sopedid.pdf
- http://cosmikkino.ru/sadm_files/24055375068.pdf
- https://mauspro.net/upload/files/jolupezezexukojatob.pdf
- https://coolinterier.sk/upload/files/96733697708.pdf
- http://piazzademarini3ge.com/userfiles/files/situkawonunivawanidegojuw.pdf
- http://bannails.com/fckeditor_userfiles/file/pifofilive.pdf
- http://apsara.ru/userfiles/file/37246237888.pdf
- http://gr-chem.com/upload/files/54006216879.pdf
- https://jpt.mysmartedu.com/uploadimages/files/19638487549.pdf
- http://terralis.net/catalogue_dynamique/file/61913454704.pdf
- https://vaitinhdien.com/app/webroot/upload/files/42568762033.pdf
- http://shahgrp.com/uploads/4675939150.pdf
- http://asja-doll.ru/userfiles/file/jarowobogifuta.pdf
- https://www.disbel.es/ckfinder/userfiles/files/werifiwadolukufif.pdf
- http://ingegneriarossi.it/userfiles/files/xixufadut.pdf
- http://goang-hann.com/uploads/files/202109121251518922.pdf
- http://oishisushigd.com/uploads/files/19310351130.pdf
- https://www.truesdalepainting.com/wp-content/plugins/formcraft/file-upload/server/content/files/1613c1f81add92---pujotobexalezedowabosup.pdf
- http://taiwangallant.com/uploads/files/202109072027498144.pdf
- http://valeneighbors.com/userimages/revurolamogine.pdf
- http://104408017.linker.tw/files/18537750939.pdf
- https://www.accidentinjurylascruces.com/wp-content/plugins/super-forms/uploads/php/files/ifjv320cuv1iklfci3mh0a46b4/98639110288.pdf
Embedded domains
- huntic.ru
- jubangh.com
- iveducentar.com
- sonarkella.com
- cosmikkino.ru
- mauspro.net
- piazzademarini3ge.com
- bannails.com
- apsara.ru
- gr-chem.com
- jpt.mysmartedu.com
- terralis.net
- vaitinhdien.com
- shahgrp.com
- asja-doll.ru
- www.disbel.es
- ingegneriarossi.it
- goang-hann.com
- oishisushigd.com
- www.truesdalepainting.com
- taiwangallant.com
- valeneighbors.com
- 104408017.linker.tw
- www.accidentinjurylascruces.com
- www.w3.org
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report